CVE-2023-36461
Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks. This vulnerability can be used to keep all Mastodon workers busy for an extended duration of time, leading to the server becoming unresponsive. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- joinmastodon/mastodon
- Source
- security-advisories@github.com
References
- http://www.openwall.com/lists/oss-security/2023/07/06/7Mailing List
- https://github.com/mastodon/mastodon/commit/c5929798bf7e56cc2c79b15bed0c4692ded3dcb6Patch, Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9pxv-6qvf-pjwcThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/06/7Mailing List
- https://github.com/mastodon/mastodon/commit/c5929798bf7e56cc2c79b15bed0c4692ded3dcb6Patch, Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9pxv-6qvf-pjwcThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.